- π Master in AI & Emerging Technologies student at FP Nador
- π οΈ Software Engineer (FST Errachidia Alumnus)
- π Passionate about Offensive Security, Bug Bounties, and Penetration Testing
- π οΈ I design and build automation tools for recon, exploitation, and reporting
- π± Currently learning: Application Security (AppSec), Active Directory (AD) pentesting (starting), mobile pentesting (starting), and Django
- π‘ Building: a new Django project for authenticated vuln scanner/dashboard & internal tools
- π Open to internships and junior roles in Cybersecurity or Software Development
Web & API Security
- OWASP Top 10: XSS, SQLi, CSRF, IDOR, Broken Authentication, Misconfigurations, Sensitive Data Exposure ...
- API testing: JWT/bearer flaws, auth bypasses, rate-limit & logic abuses ...
- Server-side vulnerabilities: SSRF, template injection ...
- Auth/session attacks: brute force, session fixation, cookie misconfig, MFA bypass attempts ...
- Attack automation with Python scripts & safe PoCs ...
Manual + Automated Workflows
- Combining DAST with manual verification
- Secure code review: logic flaws, insecure APIs, backend/frontend vulnerabilities
- Fuzzing for web inputs & APIs
Web Tooling & Techniques
- Proxy-based testing (Burp/Caido)
- Authenticated testing + headless browser automation
- TLS/cert checks, CSP & header validation
Custom Tooling & Reporting
- Python tools for recon & structured outputs
- Professional reporting: reproducible PoCs, risk scoring, remediation guidance
- π Vulnerability Scanner Web App with Django (coming soon) β persistent scanner with editing/deleting of results, focused on automation and clear reporting
- π΅οΈ Recon Automation Tool β Python-based recon framework with structured outputs for triage
- π οΈ Django Project (In progress) β building a new Django app for authenticated dashboards & scan management


